Kyriaki Parmakki: “Your Voice AI Has One Week Left to Stay Silent About Being AI”

Kyriaki Parmakki: “Your Voice AI Has One Week Left to Stay Silent About Being AI”

In one week, every AI agent that interacts with customers (including voice agents, chatbots, and WhatsApp assistants) used by every EU business either starts telling customers what it is, or starts accumulating risk with every single conversation it has. There's no announcement, no press conference, no visible switch. On August 2, exposure quietly starts compounding, and most business owners don't realize the clock is already running.

Recent headlines about the EU “delaying” parts of the AI Act made that easier to miss. What actually got pushed back to December 2027 and even later for AI built into products like medical devices (2028). The rule that hits in a week, Article 50, covers something much more common: any AI that talks to a customer or produces content on a business's behalf has to say so, clearly, at the moment it happens. Miss it, and the risk isn't hypothetical; it's fines up to 3% of turnover, and in small markets like Cyprus, a reputation hit that spreads faster than the fine.

Kyriaki Parmakki has spent the past two years building exactly the systems and AI Agents for different industries: Marketing, Finance, Real Estate, Sales - as around 95% of processes involve AI for various practices.  As co-founder of Essere.ai, she's already engineered compliance into her own product. She answered the questions that matter most right now: what actually counts as risk, who's watching, and what a business can do about it before the deadline hits.

MK:There's a widespread belief that the EU delayed the AI Act. What actually got delayed, and what didn't?

Think of the Act as a pyramid. At the top are practices banned outright, such as social scoring, which has been in force since February 2025. In the middle sit “high-risk” systems, AI in hiring, credit scoring, and medical devices, which needed conformity assessments and human oversight. Those got pushed back through the Commission's “Digital Omnibus,” confirmed by EU institutions in May 2026, because the technical standards businesses need weren't ready. Stand-alone high-risk systems now have until December 2027.

But at the bottom of the pyramid, where most businesses actually live, chatbots, voice assistants, AI-generated content, there's Article 50: one obligation, honesty. People must know when they're talking to a machine. That rule sits in its own chapter and was never touched by the Omnibus. It becomes enforceable on August 2, exactly as scheduled.

EU delays AI Act” made a great headline. But the delayed rules affect a minority of specialized companies. The rule arriving in a week affects the majority, and the majority stopped paying attention.

MK: What happens, practically, on August 2 for a business that's done nothing?

On August 3, nothing dramatic. No inspector knocks on the door. That's the trap. What changes is the legal position: the obligation is live, and every day an undisclosed chatbot talks to customers, the business accumulates exposure, a complaint, a competitor's report, or being the unlucky first example an authority picks.

Under Article 99 of the Act, a transparency breach sits in the mid-tier of penalties, up to €15 million or 3% of global turnover for large companies. And the fix costs almost nothing. This isn't GDPR, where compliance meant months of work. For most businesses it's an afternoon. Carrying legal exposure to avoid an afternoon of work is the worst trade in business.

MK: Which Cypriot businesses are actually in scope here?

Anyone whose AI touches a customer or produces content that reaches one. Hotels with booking chatbots, and tourism is one of Cyprus's largest sectors. Clinics with appointment bots. Financial and forex firms with AI support chat, real estate agencies chatting with leads, e-shops with AI customer service. Beyond conversation, any business that publishes AI-generated marketing content has marking obligations, too.

The test I give owners is one question: Is there any point where a customer interacts with something automated or sees AI-generated content without knowing it? If yes, you're in scope.

MK: Is there a size threshold, or does a one-person business with an AI receptionist fall under this too?

No size exemption. What the law does build in, under Article 99, is proportionality: for SMEs and start-ups, each fine is capped at the lower of the fixed amount or the percentage of turnover, the opposite of how it works for large companies. A business with, say, €2 million in revenue facing a mid-tier breach is looking at roughly 3% of that, around €60,000, nowhere near the €15 million ceiling built for platforms the size of Meta or Google.

So the honest message is: you're not exempt, but you're not the target either. Compliance for a small business is genuinely easy, which is exactly why failing to do it looks worse.

MK: Walk me through what “disclosure” actually has to look like. Is a line in the terms of service enough?

No. Article 50 requires that the person interacting with the AI be clearly informed, at the latest by the moment of first interaction, not buried three clicks away on a policy page. A chatbot should say it in its first message. A voice agent should say it at the start of the call; ours introduces itself as an AI assistant in the first seconds, in whatever language the caller uses.

For AI-generated content, images, video, synthetic media, the duty is different: the output itself has to be marked as AI-generated in a machine-readable format, and systems already on the market before August 2 get a short grace period, until December 2, to meet that specific technical requirement.

The test I'd apply: would a reasonable customer, at the moment of the conversation, know they're talking to a machine? If the answer depends on them reading a legal document first, the disclosure isn't doing its job.

MK: You said you've already built this into Essere's own product. What did that actually involve?

Less than people expect, if you design for it from the start. The disclosure is built into the conversation itself: our agent introduces itself as AI in its opening, in every language it operates in, and it's constrained at the system level so it can never claim to be human, even if a caller asks directly. We keep records of conversations and consent flows so a client can demonstrate compliance if ever asked. And we host on EU infrastructure with EU data residency, because being honest about what the AI is goes hand in hand with being careful about where the data lives.

MK: What does the afternoon of compliance work actually look like for someone with, say, a WhatsApp chatbot?

Open the platform running the bot and edit its greeting so the first message identifies it as AI: “Hi, I'm the AI assistant of Business Name.” In most platforms, that's a settings change, not a development project.

Then test it like a customer: message your own bot and ask “am I talking to a human?” Make sure it answers honestly. Brief your team in fifteen minutes: what changed and who's responsible for the bot now. Write a one-page note: what the bot does, what it discloses, who checks it. That page matters if an authority ever asks a business to show it took the obligation seriously.

For a business whose entire AI presence is one WhatsApp bot, that's genuinely the whole job.

MK: What's the most common mistake you're seeing right now?

Disclosure ending up somewhere customers never look, a line in the terms of service, a footnote nobody reads. It's rarely bad intent, nobody's told these businesses where it should live. What works is putting the honesty inside the conversation itself, in the assistant's first message.

The opposite mistake is panic: owners switching their AI off entirely after hearing about the fines. That's like canceling your car because seatbelts became mandatory. The requirement isn't “don't use AI.” It's “don't pretend it's human.”

MK: What's the actual cost of waiting to fix this, compared to dealing with it now?

Honestly, most will wait, that's what happened with GDPR too. But that's exactly what makes this valuable for the minority who move now. In a market where most are unprepared, basic compliance becomes a differentiator, “our AI is transparent and compliant” is something you can say in a pitch your competitor can't.

And Cyprus already has real examples of what waiting on a compliance deadline costs a business here, not hypothetically, actual fines from the Data Protection Commissioner. Some organizations were fined - none of them were huge multinational players, they were ordinary Cypriot institutions that treated a compliance deadline as something to get to eventually, and eventually turned into an actual fine, years later, once the authority came looking.

That's the pattern I'd want a business owner to notice. Deadlines don't disappear because you're busy. They sit there quietly, and then something, a complaint, an audit, a bad month, brings the authority to your door. I think the real shift for Article 50 comes with the first enforcement stories, probably within a year. And fixing your disclosures forces you to map where AI touches your customers in the first place, which is the foundation work every business needs before AI pays off at all.

MK: The fines go up to €15 million or 3% of turnover. Who actually enforces this in Cyprus?

Those numbers describe worst-case exposure for large companies. Turnover means total revenue, and SMEs are capped at the lower threshold, not the higher one. Regarding enforcement, Cyprus has already put its structure in place and is ahead of several member states. Since January 2025, the Office of the Commissioner for Electronic Communications and Postal Regulation has been the national market surveillance and notification authority for the AI Act, with the Deputy Ministry of Research, Innovation and Digital Policy coordinating national implementation.

Realistically, will inspectors sweep hotels on August 3? No. Early enforcement across Europe will likely be complaint-driven: an annoyed customer, a competitor, or a journalist testing chatbots.

MK: Beyond fines, what's the reputational risk, especially in sectors like healthcare or finance?

The fine is survivable. The reputation damage is harder. If a patient or a client feels they were having a personal conversation and later learns it was a machine that never said so, what breaks isn't just that interaction, it's the question that follows: what else wasn't I told? Cyprus is a small market, stories travel fast here. The businesses in these sectors have the most to gain from doing this properly. When trust is your product, being open about your technology isn't a risk to manage, it's part of the service.

MK: What's the first thing a business owner reading this should do, tonight?

Go talk to your own chatbot. Open your website or WhatsApp, start a conversation, and ask it directly: “am I talking to a human?” If it tells the truth clearly, you're most of the way there. If it dodges, or you realize you don't even know what it would say, that's your answer, and your afternoon of work is waiting.

Kyriaki Parmakki is the co-founder of essere.ai, a solutions studio based in Limassol. The studio works foundations-first: it starts with the groundwork every business needs, from data management systems and CRM to project management, and once that structure is in place, adds intelligence on top; AI voice agents, custom AI agents and business automations. Its flagship product is Ciao, an AI voice receptionist built with EU AI Act compliance by design.

Marianna's note: Kyriaki Parmakki is not a lawyer, and nothing in this interview constitutes legal advice. Her answers reflect her own reading of the AI Act, conversations with lawyers, and what she and her team have concluded works best for compliance in their own business. AI regulation in this area is still young and could change; businesses should confirm their own obligations with a qualified legal advisor.

Interview by Marianna Konina, Reputation City

Loader